Privacy & Data Protection Policy
How Hackabby handles personal information, client data and security information.
1. Purpose
Hackabby respects the privacy, confidentiality and security of personal information entrusted to us. We process information for legitimate business and authorised cybersecurity purposes and apply risk-based technical and organisational safeguards.
2. Scope
This policy applies to website enquiries, client engagements, penetration testing, ASM/BAS, security assessments, incident response, cyber investigations, digital forensics, training, billing and other authorised Hackabby services.
3. POPIA roles
Depending on the engagement, Hackabby may act as a Responsible Party or as an Operator processing information on a client's documented instructions.
4. Information we may process
Depending on the service, this may include business contact information, IP addresses, logs, system identifiers, vulnerability information, security alerts, forensic artefacts, files, emails, incident data and other information reasonably necessary for the authorised engagement.
5. Purpose limitation and minimality
Hackabby seeks to process only information reasonably necessary for the agreed purpose and to avoid unnecessary collection or disclosure.
6. Information security
Appropriate safeguards may include encryption, access control, multi-factor authentication, least privilege, secure storage and transmission, endpoint and network security, logging, segregation, backups, integrity verification and secure deletion.
7. Forensic information
Where information constitutes digital evidence, Hackabby may apply enhanced controls including evidence identifiers, access restrictions, chain of custody, integrity verification and secure evidence repositories.
8. Sharing and cross-border processing
Hackabby does not sell personal information. Information may be shared only where reasonably necessary with authorised personnel, approved service providers, professional advisers, regulators, courts or law-enforcement authorities, subject to appropriate legal and confidentiality requirements. Certain cybersecurity technologies may involve cross-border processing, which should be addressed in engagement-specific documentation.
9. Retention
Retention depends on contractual, legal, forensic, litigation, security and regulatory requirements. Information should be securely deleted, destroyed, anonymised or returned when no longer reasonably required.
10. Data-subject rights
Subject to POPIA and applicable limitations, data subjects may request access, correction, deletion or object to certain processing. Identity verification may be required.
11. Contact
Privacy and POPIA enquiries should be directed through the official contact details published on www.hackabby.com. Hackabby's Information Officer details should be inserted here before publication.
